rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent. | |
| Title | rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink | |
| Weaknesses | CWE-22 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:43:06.250Z
Reserved: 2026-08-04T14:52:23.815Z
Link: CVE-2026-70460
No data.
Status : Received
Published: 2026-08-13T15:19:59.957
Modified: 2026-08-13T15:19:59.957
Link: CVE-2026-70460
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:15:05Z